ci: generate package list during compose via finalize.d
Build containers / fedora-cosmic (rawhide) (push) Successful in 11m54s
Build containers / fedora-cosmic (44) (push) Successful in 12m56s

Avoid mounting the built image with buildah (ran out of disk); the
finalize.d hook records the rpm list next to the treefile and release.sh
consumes it directly.
This commit is contained in:
2026-09-21 17:35:17 +02:00
parent 0a05b2a6bc
commit de5b0f143a
4 changed files with 29 additions and 15 deletions
+3 -3
View File
@@ -46,7 +46,7 @@ jobs:
run: |
set -xeuo pipefail
dnf install -y nodejs jq curl git createrepo_c
dnf install -y skopeo buildah
dnf install -y skopeo
dnf install -y cosign || true
if ! command -v cosign >/dev/null; then
case "$(uname -m)" in
@@ -114,5 +114,5 @@ jobs:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: |
buildid="$(cat .buildid)"
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${oci}"
pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt"
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}"
+7
View File
@@ -198,4 +198,11 @@ fi
"${MANIFEST}" \
"${OCI_ARCHIVE}"
# The finalize.d hook records the installed package list next to the treefile.
manifest_dir="$(dirname "${MANIFEST}")"
if [[ -f "${manifest_dir}/packages-current.txt" ]]; then
cp "${manifest_dir}/packages-current.txt" "${BUILD_DIR}/packages-current.txt"
echo "Package list: ${BUILD_DIR}/packages-current.txt"
fi
echo "Built: ${OCI_ARCHIVE}"
+12
View File
@@ -0,0 +1,12 @@
#!/bin/bash
# Runs in the target root during `rpm-ostree compose image` (edition 2024
# finalize.d hook). Records the installed package list next to the treefile so
# build.sh can hand it to release.sh without having to mount the built image.
set -euo pipefail
if [[ -z "${RPMOSTREE_WORKDIR:-}" ]]; then
echo "RPMOSTREE_WORKDIR not set, skipping package list" >&2
exit 0
fi
rpm -qa --root "${PWD}" --qf '%{NAME} %{EVR}\n' | sort > "${RPMOSTREE_WORKDIR}/packages-current.txt"
+7 -12
View File
@@ -2,7 +2,7 @@
# Generate a package changelog for a freshly built image and publish it as a
# Gitea release (instead of committing JSON files under changelogs/).
#
# Usage: release.sh <image> <distro> <buildid> <ociarchive>
# Usage: release.sh <image> <distro> <buildid> <packages-file>
#
# The full package list is attached to each release as
# packages-<image>-<distro>.txt
@@ -10,21 +10,21 @@
set -euo pipefail
if [[ $# -lt 4 ]]; then
echo "Usage: $0 <image> <distro> <buildid> <ociarchive>" >&2
echo "Usage: $0 <image> <distro> <buildid> <packages-file>" >&2
exit 1
fi
IMAGE="$1"
DISTRO="$2"
BUILDID="$3"
OCI_ARCHIVE="$4"
PACKAGES_FILE="$4"
GITEA_URL="${GITEA_URL:-https://git.plabble.org}"
GITEA_REPO="${GITEA_REPO:-Misthios/bootc-images}"
TOKEN="${RELEASE_TOKEN:-${GITHUB_TOKEN:-}}"
[[ -n "${TOKEN}" ]] || { echo "RELEASE_TOKEN (or GITHUB_TOKEN) is required" >&2; exit 1; }
[[ -f "${OCI_ARCHIVE}" ]] || { echo "Missing OCI archive: ${OCI_ARCHIVE}" >&2; exit 1; }
[[ -f "${PACKAGES_FILE}" ]] || { echo "Missing package list: ${PACKAGES_FILE}" >&2; exit 1; }
API="${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}"
RELEASE_TAG="${IMAGE}-${DISTRO}.${BUILDID}"
@@ -41,14 +41,9 @@ if curl -fsSL -H "Authorization: token ${TOKEN}" \
exit 0
fi
# --- package list from the built image -------------------------------------
echo "Extracting package list from ${OCI_ARCHIVE} ..."
export STORAGE_DRIVER=vfs
ctr="$(buildah from "oci-archive:${OCI_ARCHIVE}")"
mnt="$(buildah mount "${ctr}")"
rpm -qa --root "${mnt}" --qf '%{NAME} %{EVR}\n' | sort > "${WORK}/packages-current.txt"
buildah unmount "${ctr}"
buildah rm "${ctr}" >/dev/null
# --- package list from the build -------------------------------------------
echo "Using package list ${PACKAGES_FILE} ..."
cp "${PACKAGES_FILE}" "${WORK}/packages-current.txt"
# --- previous package list from the last release ---------------------------
# Walk the release list (newest first) until we find the newest release for